Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.7%—Pivotal Software Cloud Foundry UAAPivotal Software Cloudfoundry UAA Release19/11/201817/6/2026
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges.
ModificadaCrítica (9.8)1.1%—Pivotal Software Cloudfoundry UAAPivotal Software Cloudfoundry UAA Release5/10/201817/6/2026
Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.
ModificadaMedia (6.5)1.2%—Cloudfoundry Garden-runc18/9/201817/6/2026
Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create and delete apps with crafted file attributes to cause a denial of service for new app instances or scaling up of existing apps.
ModificadaMedia (5.9)1.6%—Cloudfoundry Cf-releaseCloudfoundry Java Buildpack11/7/201817/6/2026
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications to be vulnerable, they must have been staged using automatic buildpack detection, passed through…
ModificadaMedia (6.5)1.1%—Cloudfoundry Loggregator6/6/201817/6/2026
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not handle errors thrown while constructing certain http requests. A remote authenticated user may construct malicious requests to cause the traffic controller to…
ModificadaMedia (6.8)1.0%—Cloudfoundry Loggregator6/6/201817/6/2026
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not validate app GUID structure in requests. A remote authenticated malicious user knowing the GUID of an app may construct malicious requests to read from or write…
ModificadaAlta (7.2)1.8%—Cloudfoundry Cf-deploymentPivotal Software Cloud Foundry Diego6/6/201817/6/2026
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps running on that Diego Cell.
ModificadaMedia (5.3)1.1%—Cloudfoundry Cf-deploymentCloudfoundry Routing-release23/5/201817/6/2026
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.
ModificadaAlta (7.2)1.3%—Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-releaseCloudfoundry Cf-deployment15/5/201817/6/2026
Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the…
ModificadaMedia (6.5)1.1%—Cloudfoundry Garden-runcCloudfoundry Cf-deployment30/4/201817/6/2026
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell.
ModificadaMedia (5.3)0.97%—Cloudfoundry Capi-releaseCloudfoundry Cf-release18/4/201817/6/2026
Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An application developer may create an application with a route that conflicts with a platform service route and receive traffic intended for the service.
ModificadaCrítica (9.6)0.87%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic Runtime29/3/201817/6/2026
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a…
ModificadaAlta (8.8)0.92%—Cloudfoundry Cf-deploymentCloudfoundry Garden-runc-release29/3/201817/6/2026
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.
ModificadaAlta (8.1)0.98%—Cloudfoundry Silk-release27/3/201817/6/2026
Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an application security group (ASG) that overlaps with the Silk overlay network, any applications can reach any other application on the network regardless of the configured…
ModificadaAlta (8.1)1.1%—Cloudfoundry Capi-release27/3/201817/6/2026
Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malicious user can predict the location of application blobs and leverage path traversal to create a malicious application that has the ability to overwrite arbitrary files on…
ModificadaAlta (8.1)1.2%—Cloudfoundry Cf-deploymentCloudfoundry Routing-release19/3/201817/6/2026
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with developer privileges could use this vulnerability to steal data or cause denial of service.
ModificadaAlta (8.8)0.98%—Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Cf-release19/3/201817/6/2026
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerability where a refresh token that would otherwise be insufficient to obtain an…
ModificadaAlta (7.5)1.3%—Cloudfoundry Garden19/3/201817/6/2026
In Garden versions 0.22.0-0.329.0, a vulnerability has been discovered in the garden-linux nstar executable that allows access to files on the host system. By staging an application on Cloud Foundry using Diego and Garden installations with a malicious custom buildpack an end user could read files on the host system…
ModificadaMedia (6.1)0.83%—Cloudfoundry Cf-releasePivotal UAAPivotal UAA Bosh4/1/201817/6/2026
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross-site scripting (XSS) attack is possible in the clientId parameter of a request to the UAA OpenID…
ModificadaMedia (6.5)0.95%—Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Cf-release28/11/201717/6/2026
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from creating subdomains to an already existing route that belongs to a…
ModificadaMedia (5.3)1.1%—Cloudfoundry Cf-releaseCloudfoundry Uaa-release27/11/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1). In some cases, the UAA allows an authenticated user for a particular client to revoke client tokens for other users on the same…
ModificadaAlta (8.8)1.0%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage."
ModificadaCrítica (9.8)1.2%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
ModificadaCrítica (9.8)1.2%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessions.
ModificadaAlta (8.8)0.76%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
Orbitaley — Vulnerabilidades